The computer’s hypervisor,
which runs below the VM running the untrusted OS and apps,
decrypts the data and associates hardware tags with every memory word of the memory allocated to hold the decrypted data called a secure data compartment within the memory.